Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-25550
Seagull Software BarTender Unauthenticated RCE via .NET Remoting Service
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0142 72.0 —
AFFECTED
Product Versions Fixed
BarTender 2010 unspecified —
BarTender 2016 unspecified —
BarTender 2019 unspecified —
TIMELINE
Feb 2 Reserved by VulnCheck
Jun 4 Published (CNA: VulnCheck)
Sep 2 EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added.
Sep 16 EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added.
Description
Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singleton endpoint — BarTenderSystem for BarTender 2016 <= R9, and DataServiceSingleton for BarTender 2019 <= R10 — configured with BinaryServerFormatterSinkProvider and TypeFilterLevel set to Full. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling to read or write arbitrary files on the server using the .NET WebClient class, or coerce NTLMv2 authentication by supplying a UNC path to an attacker-controlled server, enabling sensitive credential disclosure, remote code execution, or lateral movement depending on service account privileges and network environment. The service runs in the context of NT AUTHORITY\\SYSTEM. This vulnerability is corrected in BarTender 12.0.1. Users of affected releases should upgrade to BarTender 12.0.1 or later.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| February 2, 2026 | Reserved | Reserved by VulnCheck |
| June 4, 2026 | Published | Published (CNA: VulnCheck) |
| September 2, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added. |
| September 16, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added. |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-25550 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.